AsiaTechDaily – Asia's Leading Tech and Startup Media Platform
AI security is entering a more complicated phase. The concern is no longer limited to whether an AI model can generate malicious code or identify a vulnerability. Increasingly capable models are beginning to demonstrate the ability to navigate complex systems, adapt to obstacles and take multiple actions without direct human instruction.
OpenAI’s disclosure of a July 2026 incident involving its internal cybersecurity evaluations illustrated the shift. Several models circumvented controls intended to isolate them from the internet, exploited vulnerabilities in shared infrastructure, communicated through unauthorized channels and accessed third-party systems, including Hugging Face. OpenAI said its models are now sufficiently powerful, persistent and collaborative to find and exploit weaknesses across multiple computer systems without adequate safeguards. It also warned that many external models, including open-source models, will soon reach comparable capabilities.
That raises a difficult question for the AI industry: if advanced cyber capabilities are increasingly available beyond closed frontier models, does the openness of AI create a different security equation?
For much of the generative AI era, the most capable models were largely controlled by a small number of companies. That created a security advantage of sorts: providers could restrict access, monitor usage, update safeguards and withdraw models when necessary. That advantage is becoming less durable. The UK’s AI Security Institute found in its latest testing that leading open-weight models such as GLM-5.2 and DeepSeek V4-Pro performed similarly on its cyber evaluations to closed models released four to seven months earlier. AISI said this gap had been six to 10 months through most of 2025.
The significance is not simply that open models are becoming more capable. It is that the window during which cyber defenders can prepare for capabilities available only through controlled systems may be getting shorter. Open-weight models can be downloaded, modified and deployed privately. That creates benefits for organizations that need customization or local deployment, but it also removes some of the controls available to a centralized model provider.
The argument for open models is not simply ideological. Open weights allow researchers to inspect and evaluate models, organizations to customize them, and developers to run them without depending entirely on a model provider. The International AI Safety Report 2026 identifies these as significant benefits, particularly for research, innovation and access. But it also highlights a fundamental tradeoff: safeguards on open-weight models are easier to remove, usage is harder to monitor, and once model weights are released, they cannot be universally recalled.
This makes open-weight security fundamentally different from conventional software security. A September 2026 UK government review found that established cybersecurity practices do not transfer cleanly to AI artifacts such as model weights, training datasets and fine-tuning pipelines. It identified risks including weight tampering, dataset poisoning, insecure fine-tuning and weak model provenance. Of the 10,000 most-downloaded Hugging Face models examined in the review, only 15 carried security-relevant documentation. The challenge, therefore, is not simply whether a model is open or closed. It is whether enterprises can establish where a model came from, what has been done to it, how its safeguards have been tested and what happens when it is integrated into a larger system.
There is a competing argument that concentrating AI security inside a small number of providers can itself create risks. While conversing with AsiaTechDaily, Eugene Cheah, CEO and Co-Founder of Featherless.ai, argued that proprietary systems should not automatically be considered more secure:
“It is a myth that proprietary systems are automatically more secure than open-source code. This was debunked decades ago in software and continues now in the AI age. It feels like many seem to have forgotten the basics of cybersecurity. Locking AI infrastructure behind closed interfaces only increases security risks. If researchers can get access to model weights via open-source, they can test vulnerabilities and create safeguards faster, while leaving control to just a handful of vendors hides critical vulnerabilities until a major breach occurs.
“Recent attempts to limit model distillation and open-weight distribution are motivated by market protectionism, not safety issues. A broad coalition of technology companies and open-source proponents agree that such measures will have a negative effect and hamper competitiveness. Mandating rigid safety frameworks designed for frontier labs forces enterprises back into locked ecosystems. Protecting open models preserves market competition while keeping corporate intellectual property secure.
“Apart from security issues, closed models are increasingly failing to live up to expectations. They are more expensive and are diminishing returns for enterprises. General models achieve maximum effectiveness of 70% on specialised tasks, but enterprise deployment requires at least 90% effectiveness. Bigger pre-trained models will not solve this problem. The true solution is to train small open models on enterprise-specific data for each business process. AT&T demonstrated this approach with OTel 2.0, a specialised open-source model built specifically for the telecoms industry, using 400 billion telecom-specific tokens selected from more than 1 trillion processed tokens.”
Cheah’s position is a counterargument to the centralized-control model, rather than evidence that open-weight systems are inherently safer. The broader research points to genuine tradeoffs on both sides.
The emerging challenge is increasingly about the infrastructure surrounding AI. Recent UK government research identified gaps in verifying the integrity of model weights and training data, tracking the provenance of third-party models, and connecting the AI model attack surface with the traditional IT infrastructure supporting generative and agentic AI. That distinction matters because increasingly autonomous models do not operate in isolation. They interact with APIs, cloud environments, code repositories, enterprise systems and other digital infrastructure.
As a result, AI security increasingly requires controls across multiple layers:
The Hugging Face incident does not establish that open-weight AI is inherently more dangerous, just as access to source code does not automatically make a system safer. What it demonstrates is that the underlying capabilities of AI systems are advancing quickly enough to challenge existing assumptions about security and control. AISI’s narrowing capability gap suggests that open-weight models may increasingly acquire advanced cyber capabilities within months rather than years of their closed counterparts.
That leaves enterprises with a more difficult security problem. They will have to evaluate not only which model they use, but how it was developed, what safeguards remain in place, where it runs, who can modify it and how its behavior can be monitored. The next phase of AI security will therefore be less about choosing between “open” and “closed” models and more about building security systems capable of operating at the same speed, scale and autonomy as the models themselves.